criticalCVSS 9.9Vulnerability

CVE-2026-92948

## Summary On Node.js 24 and newer, `vm2` can expose the host `node:test` module to sandboxed `NodeVM` code when the embedder explicitly allows the `node:test` builtin. Sandbox code can reach that module through `require('node:node:test')` and call `run()` with attacker-controlled `execArgv`. `node:test.run()` starts a separate Node process for process-isolated test execution and forwards the supplied `execArgv` values to that process. Supplying `--eval=<JavaScript>` therefore executes arbitrary JavaScript in an unrestricted host Node process, outside the `NodeVM` sandbox. The PoC confirms that direct sandbox imports of `fs`, `child_process`, `module`, and `process` remain denied before the spawned process imports host `fs` and writes a harmless marker. ## Affected versions and environment - Package: `vm2` - Affected versions: `>=3.9.6, <=3.11.5` - Latest reproduced version: `3.11.5` - Reproduced runtime: Node.js `v24.18.0` - Exact path is not present on Node.js 22 because `module.builtinModules` does not expose the scheme-only `node:test` entry there - Configuration prerequisite: ```js require: { builtin: ['node:test'], external: false } ``` The lower version boundary was tested directly: `[email protected]` blocks `require('node:node:test')`, while `[email protected]` permits the exploit path. Representative releases through `3.11.5` were also reproduced. ## Root cause The issue is a combination of builtin admission, generic host passthrough, and prefix normalization: 1. On Node.js 24+, `module.builtinModules` includes the scheme-only key `node:test`. 2. `lib/builtin.js` builds `BUILTIN_MODULES` from that array. The family-based `DANGEROUS_BUILTINS` protection does not include `test`, so `node:test` remains eligible. 3. When the embedder explicitly allows `node:test`, `addDefaultBuiltin()` stores it through the generic loader: ```js builtins.set(key, special ? special : vm => vm.readonly(hostRequire(key))); ``` 4. In `lib/setup-node-sandbox.js`, `requireImpl()` st

Properties

severity
critical
summary
vm2: NodeVM builtin allowlist bypass via node:test.run() execArgv allows sandbox escape
cvss_score
9.9
retrieved_at
2026-10-01T19:14:01+00:00
ghsa_published
2026-10-01T15:41:31Z
source_url
https://github.com/advisories/GHSA-qhwx-74w5-xhxq
ghsa_updated
2026-10-01T15:41:32Z
ghsa_id
GHSA-qhwx-74w5-xhxq
last_source
GitHub Advisory Database
cve_id
CVE-2026-92948
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
signal_observed_at
2026-10-01T19:14:01+00:00
is_ghsa_only
false

Related Entities (4)

VULNERABLE_TO (1)

←[Software]npm/vm2

AFFECTS (1)

→[Software]npm/vm2

HAS_WEAKNESS (1)

→[Weakness]Protection Mechanism Failure

REPORTED_BY (1)

→[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-92948 (CVSS 9.9) — Ninja Signal Threat Intelligence | Ninja Signal